← Back to home

Application Privacy Policy

Published: September 21, 2026

Development-stage policy. The Google Ads application has not launched and does not currently collect Google Ads data. The handling described below is the policy selected for its launch and must be implemented before any production account is connected.

1. Who we are and when this policy applies

Veylantic is the project and business brand responsible for this internal application. For privacy questions or requests, contact pitipiwpiwwiwwiw1996@gmail.com. This policy covers the planned Google Ads integration and is separate from the corporate website privacy policy. The application is not yet built or available for production use. The provisions below describe how data will be handled when it launches; no Google Ads data or OAuth tokens are currently collected by this application.

2. Purpose and intended users

The application will be used only by authorized Veylantic personnel to review Google Ads performance reports and create or edit campaigns for accounts Veylantic is authorized to manage. Clients will not have a self-service login in the initial version. Account owners must authorize agency access, and personnel will only see accounts assigned to them.

3. Google authorization and permissions

The application will request the Google Ads OAuth scope https://www.googleapis.com/auth/adwords through Google’s consent screen. This scope supports both reporting and account changes; it is not a read-only permission. Access will remain limited by the authorizing user’s Google Ads permissions and the functions described here. Offline access and refresh tokens will support scheduled report synchronization. The application will not request Gmail, Google Drive, Calendar, or Contacts access, or collect Google passwords.

4. Data accessed and why

The application will retrieve Google Ads customer and manager account IDs, account names, currency and time-zone settings to identify authorized accounts. It will retrieve campaign and ad-group IDs, names, status, budgets, bidding settings, ads, and keyword configurations to display existing campaigns and perform operator-approved changes. Reporting data will include dates, impressions, clicks, cost, conversions, and conversion value to produce performance summaries. It will store OAuth access and refresh tokens solely to maintain the authorized connection. Internal user identifiers, account assignments, timestamps, operation types, and error codes will support access control, troubleshooting, and accountability.

5. Data excluded from the initial version

The initial version will not ingest Customer Match lists, customer email or phone lists, lead-form submissions, individual conversion records, or other directly identifying audience data. It will not implement offline conversion uploads, audience creation, search-term reports, or raw API-response logging. Any expansion into new data categories will require an updated notice and any necessary consent before access begins.

6. How data is used and campaign actions

Google Ads data will be used only for the connected account’s reports and authorized campaign management. Scheduled tasks will refresh reports but will not autonomously change campaigns. An authorized operator must review the target account, proposed changes, and budget or bid effects before submitting a create or edit operation. We will not sell account data, combine it across clients for profiling, build advertising audiences from it, transfer it to data brokers, or use it to train general-purpose AI models.

7. Where data will be stored

The selected launch architecture uses Amazon Web Services (AWS) hosting and a private PostgreSQL database in the Singapore region for application records, with a dedicated secrets store for OAuth credentials. This infrastructure has not yet been provisioned. Production processing will not begin until it is configured and tested. Google processes API authorization and account operations on its own infrastructure. Information voluntarily emailed to our Gmail support address is processed by Google’s email service; do not email credentials or raw customer reports.

8. Security and human access

Before launch, the implementation will enforce HTTPS in transit, encryption at rest, encrypted server-side credential storage, least-privilege service roles, staff authentication with a second factor, account-level authorization checks, and redaction of secrets from logs. Tokens will not be embedded in public pages, browser storage, downloadable reports, or source code. Authorized staff may access the account information necessary to deliver the expressly authorized reporting and management functions. Support access to other specific data will require the account owner’s permission unless needed for security or a legal obligation. These are launch requirements, not a statement that an unbuilt backend already provides them.

9. Retention periods

Cached reports will be deleted no later than 90 days after retrieval. Campaign configuration snapshots will be refreshed as needed and retained for at most 30 days after their last synchronization. Minimal audit records will be retained for 180 days; technical logs for 30 days. OAuth access tokens will be short-lived and replaced as needed; refresh tokens will be retained only while the connection is active. Revoked or disconnected credentials will be deleted from our active secrets store within 24 hours. Database backups will rotate within 7 days; the token store will be excluded from these backups.

10. Who receives information

Google will receive authorization requests, report queries, and the campaign instructions needed to provide the integration. AWS will process hosted application data only as the infrastructure provider for the purposes described above. Authorized Veylantic staff will access only the accounts required for their work. We will not provide account data to unrelated advertisers, data resellers, or AI providers. Information may be disclosed where legally required or to investigate security incidents, limited to what is necessary. Hosting in Singapore and Google’s global services may involve international processing. Any material provider or location change will be disclosed before that processing begins.

11. Disconnecting and revoking access

The application will provide a Disconnect control that stops scheduled synchronization, rejects queued changes for that connection, and initiates token revocation and credential deletion. You can also remove access directly from Google Account connections. Revocation prevents future authorized access but does not automatically delete previously stored records. Disconnecting will not delete campaigns or historical records in Google Ads, and completed advertising actions will not be reversed automatically.

12. Access, correction, and deletion requests

Email pitipiwpiwwiwwiw1996@gmail.com with the subject “Veylantic data request” and the relevant Google Ads customer ID. Do not include tokens or passwords. We will verify that you are authorized for that account, acknowledge the request within 7 calendar days, and complete access, correction, or deletion requests within 30 calendar days after verification. A deletion request will also disconnect the affected account. Linked data will be removed from active storage within that period and from rotating backups within a further 7 days. Audit records tied to that account will be deleted or stripped of identifying links. If a legal preservation obligation prevents deletion, we will explain the basis where permitted, restrict the retained data, and delete it when that obligation ends.

13. Google API data restrictions

Veylantic will handle data obtained through Google APIs in accordance with the Google API Services User Data Policy, including applicable Limited Use requirements, and Google Ads API policies. Access, use, and permitted transfers will be limited to the features and purposes disclosed here. Consent to connect an account is not consent to unrelated marketing or secondary use of that account’s data.

14. Policy updates and contact

Published: September 21, 2026. This development-stage policy will be reviewed against the implemented application before launch. Material changes will be published here and communicated to affected users; new data uses will require any necessary renewed consent before they begin. Questions and complaints: pitipiwpiwwiwwiw1996@gmail.com.